DLA-4754-1

NameDLA-4754-1
Descriptionthunderbird - security update
SourceDebian LTS
ReferencesCVE-2026-74934, CVE-2026-74935, CVE-2026-74936, CVE-2026-74939, CVE-2026-74940, CVE-2026-74941, CVE-2026-74942, CVE-2026-74943, CVE-2026-74944, CVE-2026-74945, CVE-2026-74946, CVE-2026-74948, CVE-2026-74949, CVE-2026-74953, CVE-2026-74957, CVE-2026-74959, CVE-2026-74960, CVE-2026-74962, CVE-2026-74963, CVE-2026-74964, CVE-2026-74965, CVE-2026-74967, CVE-2026-74969, CVE-2026-74971, CVE-2026-74972, CVE-2026-74973, CVE-2026-74974, CVE-2026-74976, CVE-2026-74983, CVE-2026-74987, CVE-2026-74990

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
thunderbird (PTS)bullseye1:115.12.0-1~deb11u1vulnerable
bullseye (security)1:140.14.0esr-1~deb11u1fixed
bookworm1:140.12.0esr-1~deb12u1vulnerable
bookworm (security)1:140.14.0esr-1~deb12u1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
thunderbirdsourcebullseye1:140.14.0esr-1~deb11u1
thunderbirdsourcebookworm1:140.14.0esr-1~deb12u1

Search for package or bug name: Reporting problems